AAISM Exam Questions & Answers
ISACA Advanced in AI Security Management Exam • Isaca
100% money-back guarantee
Sample AAISM Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
Which of the following strategies is the MOST effective way to protect against AI data poisoning?
AAISM directs organizations to prevent training-time attacks by hard-gating data ingestion with provenance checks, schema and label validation, sanitization, and anomaly/outlier detection prior to model training. These controls most directly block poisoned records from entering the pipeline and are prioritized over architectural complexity or sheer data volume. Diversity of sources can improve representativeness but does not reliably stop adversarial contamination.
From a risk perspective, which of the following is the MOST important step when implementing an adoption strategy for AI systems?
AAISM guidance states that when adopting AI, the most important step is to conduct a risk assessment and update the enterprise risk register. This ensures AI-specific risks are identified, documented, and integrated into the organization's existing governance structures. Benchmarking peers provides context but does not address internal risk. Implementing methodologies and frameworks are important, but they precede or follow the assessment process. The decisive step that connects adoption to enterprise risk governance is updating the risk register with AI-specific risks.
AAISM Study Guide -- AI Risk Management (Integration with Enterprise Risk Management)
ISACA AI Security Management -- Risk Assessment and Register Updates
A regulator warns of increased risk of AI re-identification attacks on anonymized datasets. What should the information security manager do FIRST?
AAISM states that anonymization is not permanent and may be reversible through re-identification attacks. The first action should be to evaluate and measure the actual privacy risk through:
* adversarial re-identification testing
* privacy audits
* monitoring for misuse
This provides the factual basis needed before making destructive or operational decisions.
Access control (D) is important but not the FIRST step. Deleting datasets (B) is premature. Assuming anonymization is permanent (A) violates AI privacy principles.
An attack has occurred on an AI system that has been in use for two years. Which of the following would BEST mitigate the impact of the attack?
When an AI system experiences an attack after being in production for an extended period, the most effective mitigation strategy is to update the deployed training data with new adversarial data. This process strengthens the model's resilience by retraining it to recognize and resist attack vectors that were previously unknown or unaccounted for. According to the AI Security Management (AAISM) framework, risk mitigation for AI systems must address model robustness through adversarial retraining, data quality improvement, and model lifecycle hardening rather than relying solely on reactive measures.
Why Option B is Correct:
Incorporating adversarial examples into the training set enhances the system's ability to correctly classify and withstand malicious inputs.
This approach directly mitigates the vulnerability exploited in the attack and supports a proactive, continuous risk management cycle.
Why Other Options Are Incorrect:
Option A: Monitoring helps detect suspicious activity but does not resolve the underlying vulnerability.
Option C: Concealing confidence scores may reduce model transparency but does not address the attack mechanism or its root cause.
Option D: Implementing access controls protects the model's architecture but does not improve model robustness against input manipulation attacks.
Exact Extract from Official AAISM Study Guide:
''AI risk management requires continuous improvement following incidents. After an adversarial or data poisoning event, the preferred risk treatment involves retraining the model using adversarial data and updated datasets to enhance robustness. This ensures the AI model adapts to evolving threat landscapes rather than merely restricting access or obscuring outputs.''
AI Security Management (AAISM) Body of Knowledge: AI Risk Treatment and Mitigation Strategies, Adversarial Robustness and Resilience Engineering.
AI Security Management Study Guide: Model Lifecycle Security, Continuous Risk Treatment through Adversarial Retraining.
ISO/IEC 23894:2023, Clause 8.3.2 --- Risk treatment through robustness improvement and adversarial data inclusion.
Which of the following would BEST ensure a proper business continuity plan (BCP) is in place for an AI solution?
Effective AI BCP requires validation through exercises and controlled failover tests to prove recovery objectives can be met in practice. Merely documenting backups (Option D), hardening access (Option B), or improving monitoring (Option A) does not confirm that the AI stack---data pipelines, feature stores, model registries, inference services, and dependent infrastructure---can actually fail over and recover within RTO/RPO. AAISM prescribes periodic BCP/DR testing (including model artifact restoration, configuration reconstitution, dependency failover, and data pipeline continuity) to verify readiness and identify gaps before real incidents.
Get access to all 255 verified questions with detailed answers.
Unlock All AAISM Questions